1.risk Management Process Cycle
1.risk Management Process Cycle
Process/cycle
UNIT 8
Session learning objectives
• After completing this session you should be able to:
• Evaluate the impact of risks upon an organisation
• Link various stages into a risk identification process
• Methods for identifying ,assessing and quantifying risks.
Introduction
• Risk identification is a deliberate and systematic effort to identify and document
the Institution’s key risks. The objective of risk identification is to understand
what is at risk within the context of the Institution’s explicit and implicit objectives
and to generate a comprehensive inventory of risks based on the threats and
events that might prevent, degrade, delay or enhance the achievement of the
objectives.
• This necessitated the development of risk identification guidelines to ensure
that Institutions manage risk effectively and efficiently. Modern-day businesses
face various risks to their day-to-day operations. For example, a company’s
network may be hacked, compromising employee, and customer data. Natural
disasters such as hurricanes, tornadoes, and wildfires can also impact an
organization’s ability to operate.
• Ensuring the safety of a company and its employees is about more than being
able to react quickly to a threat. Effective risk management involves preparing
for a threat before it happens.
Risk management Process
[Link] Identification
[Link] analysis /Assessment(Evaluating)
3. Risk Treatment/Risk Strategies
[Link] Monitoring And Reporting
Risk Management process which is constituted of two main elements:
• Risk Analysis and Risk Control
• Risk Analysis process covers the identification, estimation and
evaluation of risk. Proper implementation of all stages in this process
will result in the recognition of potential risk events affecting supply
chain. The term risk assessment is also interchangeably used in
referring to risk analysis.
• Risk Control looks at how risks can be controlled and the strategies
that an organisation can adopt to control risk not all risk events fall
under the category of disruption risk events, and therefore the
potential impact caused by an individual risk event needs to be
carefully.
[Link] Identification
• Risk identification should be inclusive, not overly rely on the inputs of a few
senior officials and should also draw as much as possible on unbiased
independent sources, including the perspectives of important stakeholders.
• A stake holder is someone who has vested interest in what an organisation is
doing. Identifying potential risks:
• In this step, the project team and stakeholder identify potential risks that
could impact the project. This includes internal factors, such as resource
shortages, and external factors, such as changes in regulations or market
conditions.
• The risk identification process defines the scope of a project or program. It
consists of various steps outlining the project’s boundaries and requirements.
Also, this ensures that it considers and accounts for all potential risks. These
stages include:
The following are key steps necessary to effectively identify risks
from across the Institution:
1. Understand what to consider when identifying risks
2. Gather information from different sources to identify risks
[Link] risk identification tools and techniques
[Link] the risks
5. Document the risk identification process
[Link] the effectiveness of the risk identification process.
Classification of risks in a business
-Commercial risk-commercial risk can come from an number of areas including
• volatiles market places
• material costs
• selection of supply chain partners
• failure of business
• underperformances in the supply.
• Lack of knowledge of new markets or products and poor board direction often serve to exacerbate
these risks.
-Financial risks- Cash flow, Capital funding, Credit rating etc
-Directional risks-This simply means an organisation may select a direction that is the wrong one
or at least, it may turn out to be the wrong one. An example ,a company or business may set up to
dominate a market ,by acquiring some competitors and driving others out of the business by
aggressive pricing techniques
-Environmental risks- These are risk that encompasses changes to environmental legislation
such as the waste or pertain to changes in the [Link] could even cover where residential
housing is built right up to a factory s perimeter thus altering the altering the factory environment
awareness needs
Environmental risks
1. Governmental regulatory concerns
2. Changes in exchange rates
3. Rapid changes in technology
4. Competition risk
5. Insufficient public utility supply
External sources of Risks
• Sources of risk in an organisation can emanate from both inside and outside an
organisation.
• Risks can be created through the selection and adoption of certain strategies, tactics
and projects in an organisation.
• Risk in an organisation can be created through the following
[Link] level
[Link] level
[Link] level
• Focus points of risk identification To ensure comprehensiveness of risk identification
the Institution should identify risk factors through considering both internal and
external factors, through appropriate processes.
Risk identification
• Risk identification enumerates all types of risks in the supply
chain.
Common risk identification methods include
• Delphi method, checklists
• Module decomposition method and scenario analysis
(presented a conceptual model for identifying and assessing
supply chain risks.
• Scenario planning in proactive management of supply chain
risks.
[Link] risk identification
• Strategic risk identification to identify risks emanating from the strategic
choices made by the Institution, specifically with regard to whether such choices
weaken or strengthen the Institution's ability to execute its Constitutional
mandate:
• Strategic risk identification should precede the finalization of strategic choices to
ensure that potential risk issues are factored into the decision making process
for selecting the strategic options.
• Risks inherent to the selected strategic choices should be documented,
assessed and managed through the normal functioning of the system of risk
management; and strategic risks should be formally reviewed concurrently with
changes in strategy, or at least once a year to consider new and emerging risks.
Risks created at strategic level can in form of the following
[Link]
[Link]
3. Acquisition of other business
• Strategic risk management is based around alternative courses of action which an
organisation may take to minimize the effects of potential risks which may detract ,or
even prevent the strategy being achieved.
• The risks could affect the continuing survival of the organisation.
• An organisation strategy implements the vision and mission of organisation founders
or its highest management level .
• The strategy flows down into objectives which will be achieved by applying resources
–Money, Manpower, Machinery together with appropriate skills and knowledge.
[Link] risk
• Operational risk identification to identify risks concerned with the Institution’s
operations: Operational risk manifests itself at a lower level in the management of
the organisation can threaten business survival. An example can be failure to
manage debtors and cash flow can quickly and lead to bankruptcy
• Operational risk identification should seek to establish vulnerabilities introduced by
the following :
• Employees
• Internal processes and systems,
• Contractors
• Regulatory authorities and external events.
• Operational risk identification should be an embedded continuous
process to identify new and emerging risks and consider shifts in
known risks through mechanisms such as:
• Management and committee meetings
• Environmental scanning
• Process reviews and the like.
• Operational risk identification should be repeated when changes
occur, or at least once a year, to identify new and emerging risks.
Advantages of risk identification
• Early identification of potential risks.
• Improved planning and preparation for potential risks.
• A better understanding of the risks involved in a project.
• Improved communication and collaboration among stakeholders.
Disadvantages
• Time and resource consumption.
• Difficulty in accurately predicting all risks.
• Potential for over-analyzing risks and losing focus on the project’s
objectives.
2. Risk Analysis
Risk analysis is the procedure of analyzing and recognizing any kind of risk that could
adversely affect the primary business objective or any critical projects that are about to take
place in an organization in regards to avoiding or to take necessary initiatives to reduce such
risks in the organization.
Risk Analysis is a process that helps you to identify and manage potential problems that could
undermine key business initiatives or projects. However, it can also be applied to other
projects outside of business, such as organizing events or even buying a home!
Risk is made up of two parts: the probability of something going wrong, and the
negative consequences if it does.
Risk can be hard to spot sometimes an organisation can be hit by a consequence that didn’t
planned for, costs, time, and reputations could be on the line. Similarly, overestimating or
overreacting to risks can create panic, and do more harm than good.
This makes Risk Analysis an essential tool.
It can help you to identify and understand the risks that you could face in your role.
It can helps to manage these risks and minimize their impact on an organisation plans.
Assessing the likelihood and impact:
• Once potential risks have been identified, the next step is to assess the
likelihood and impact of each risk. The likelihood refers to the probability of the
risk occurring, while the impact refers to the potential consequences if the risk
does occur.
Prioritizing risks:
• Based on the likelihood and impact of each risk, the risks should be prioritized so
that the most critical risks can be addressed first. This ensures that the project’s
limited resources go toward the most important risks.
Developing risk mitigation plans:
• For the most critical risks, the project team should develop risk mitigation plans
to minimize the potential impact of the risks. Hence, this may include purchasing
insurance, making changes to the project schedule, or developing contingency
plans.
How and why the risk can happen (i.e. causes and consequences).
• The existing internal controls that may reduce the likelihood or
consequences of the [Link] is essential when identifying a risk to
consider the following three elements:
[Link]/event - an occurrence or a particular set of
circumstances
2 .Causes - the factors that may contribute to a risk occurring or
increase
[Link] likelihood of a risk occurring and consequences and the
outcome(s) or impact(s) of an event.
• It is the combination of these elements that make up a risk and this level
of detail will enable an Institution to better understand its risks.
Carrying out a Risk Analysis
• To carry out a Risk Analysis,
1. Identify the possible threats that you face,
2. Estimate their likely impacts if they were to happen
3. Estimate the likelihood that these threats will materialize.
• Risk Analysis can be complex, as you'll need to draw on detailed information such as
project plans, financial data, security protocols, marketing forecasts, and other
relevant information.
• However, it's an essential planning tool, and one that could save time, money, and
reputations.
Use of Risk registers
• The document in which the risks are recorded is known as the "risk register"
and it is the main output of a risk identification exercise.
• A risk register is a comprehensive record of all risks across the
Institution or project depending on the purpose/context of the register.
• There is no single blueprint for the format of a risk register and Institutions
have a great degree of flexibility regarding how they lay out their documents.
• The risk register serves three main purposes:
1. It is a source of information to report the key risks throughout the Institution,
as well as to key stakeholders
[Link] uses the risk register helps to focus their priorities risks.
3. It is to help the auditors to focus their plans on the Institution's top risks
The risks register records:
• Risk category- how and why the risk can happen "cause of risk.
• How will the risk impact the Institution if it materializes "impact on
Institution.
The qualitative and or quantitative cost should the risk materialize.
The likelihood and consequences of the risk to the Institution.
• The existing internal controls that may minimize the likelihood of the risk
occurring.
• A risk level rating based on pre-established criteria.
• Framework, including an assessment of whether the risk is acceptable or
whether it needs to be treated.
• A clear prioritization of risks (risk profile).
Process of Risk Analysis
• Analyzing risk in a project can have both a positive and negative effect. Such
effects can have both worldly and non-materialistic impacts on the
organization.
• A risk is an uncertain event that can have both positive and negative effects.
• Analysing the Risk
After identifying risk, it’s likely to understand and assess the extent of risk
and nature of risk that most likely to happen and to what extent it may occur
to the organization shall be analyzed.
• Risk analysis can be done in two ways. Quantitative and qualitative analysis
are the two approaches to risk analysis.
• Qualitative analysis
• Quantitative analysis
1. Quantitative Risk Analysis
• Quantitative risk analysis looks at the effect of the potential project risk that can be
there on the target of the project is evaluated numerically.
• The primary purpose of the Quantitative analysis is to quantify the risk exposure
and determine the size of the cost and the schedule contingencies.
2. Qualitative Risk Analysis
• Qualitative risk analysis, looks at the probability and impact of the potential project
risk that can be there on the target of the project is evaluated against a predefined
scale. It is a subjective approach.
• The primary purpose of qualitative risk analysis is to increase awareness of the
severe risk and creating risk responses to deal with and reduce the effect of these
risks on the overall project.
Methods of Risk Analysis
• Methods of Risk analysis include both Qualitative and Quantitative application
techniques. Most projects shall apply Quantitative analysis in measuring risk, which is
overlooked in terms of formal qualitative risks.
Useful qualitative risk analysis considered to be involved in project management.
• Delphi Technique – Delphi Technique uses expert opinion to identify, analyze, and
evaluate risks on an individual and anonymous basis.
• SWIFT Analysis – In SWIFT analysis, the team investigates how changes are
approved, designed, or planned that might affect the project in any way. It is a
systematic team-based approach.
• Decision Tree Analysis – This analysis is done by proposed decisions and finding
different pathways and results due to the proposed findings.
• After all the probabilities are analyzed, the course of action of modifying and verifying
When to Use Risk Analysis
Risk analysis is useful in many situations:
• When planning projects, to help you to anticipate and neutralize
possible problems.
• When deciding whether or not to move forward with a project.
• When improving safety and managing potential risks in the workplace.
• When preparing for events such as equipment or technology failure,
theft, staff sickness, or natural disasters.
• When planning for changes in your environment, such as new
competitors coming into the market, or changes to government policy.
Difference Between Risk Identification And Risk
Assessment
Risk Identification Risk Assessment
The first step in the risk management process. The next step after risk identification.
Involves identifying potential risks. Involves evaluating the impact of identified risks.
Focuses on the likelihood of risks occurring. Focuses on the consequences of risks occurring.
Risk Matrix Example
Impact/Likelihood Low Medium High
• Once areas of risk have been identified, an organization needs to monitor their internal and
external environment. This helps them to predict when risky events are becoming more likely.
It also helps to identify new risks and is tightly linked to the best practice of Supply Chain Risk
Identification.
• Risk monitoring: The implementation of a continuous control system over the threat after
treating it.
• Risk mitigation comprises all the actions that can help to prevent the risk occurring or reduce
the impact or costs of such risks. Risk mitigation will lead to a more secure business
environment and even a safer working environment if we apply it to healthy and safety issues.
• In terms of quality, the implementation of quality assurance techniques and procedures is
a way of mitigating the risk of substandard product or service. By building quality into a
product, service or process, we are clearly reducing the chances that something will go wrong
and lead to loss, damage or injury
Set timelines
• You need to set timelines and deadlines for ensuring risks are managed and treated. Make sure the most
urgent risks are dealt with first.
• Write down when things need to be checked and tick them off your risk register when they've been
complete Keep records
• It's important that you investigate and record any accidents or near-misses. This will provide you with a
document trail in case you need to justify your actions, but it will also help you to avoid similar incidents
happening again.
• Investigate the incident - what went wrong? Why? What could have prevented it? Document the details of
the incident and the answers to those questions for future reference. And act on the information.
• Records you should keep include:
• Minutes of meetings - noting important decisions and the reasons for them
• File notes - a record of important conversations in person or on the phone
• Training records - documenting any training undertaken by staff or volunteers
• Incident records - notes taken or forms completed in the event of any injury or incident.
Risk categories
General risks
• Reputational – Loss of customer or employee confidence, or damage to market
reputation.
• Procedural – Failures of accountability, internal systems, or controls, or from fraud.
• Project – Going over budget, taking too long on key tasks, or experiencing issues
with product or service quality.
• Financial – Business failure, stock market fluctuations, interest rate changes, or
non-availability of funding.
• Technical – Advances in technology, or from technical failure.
• Natural – Weather, natural disasters, or disease.
• Political – Changes in tax, public opinion, government policy, or foreign influence.
Summary